DEBIAN-CVE-2025-54409

Source
https://security-tracker.debian.org/tracker/CVE-2025-54409
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54409.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2025-54409
Upstream
Downstream
Published
2025-08-14T16:15:39.397Z
Modified
2025-11-20T10:18:24.701827Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.

References

Affected packages

Debian:11 / aide

Package

Name
aide
Purl
pkg:deb/debian/aide?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.17.3-4+deb11u3

Affected versions

0.*
0.17.3-4
0.17.3-4+deb11u1
0.17.3-4+deb11u2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54409.json"

Debian:12 / aide

Package

Name
aide
Purl
pkg:deb/debian/aide?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.18.3-1+deb12u4

Affected versions

0.*
0.18.3-1
0.18.3-1+deb12u1
0.18.3-1+deb12u2
0.18.3-1+deb12u3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54409.json"

Debian:13 / aide

Package

Name
aide
Purl
pkg:deb/debian/aide?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.19.1-2+deb13u1

Affected versions

0.*
0.19.1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54409.json"

Debian:14 / aide

Package

Name
aide
Purl
pkg:deb/debian/aide?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.19.2-1

Affected versions

0.*
0.19.1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54409.json"